CVE-2024-37370: Mit Kerberos 5

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application.

Affected products

  • Mit Kerberos 5: before 1.21.3 (fixed in 1.21.3)

Published 2024-06-28. Last modified 2026-06-17.